This Privacy Policy explains how BYN ("BYN", "we", "our", or "us") collects, uses, stores and protects personal data when you access or use the BYN mobile application ("App"), website ("Website"), and related services (collectively, the "Services").
BYN is committed to protecting your privacy and processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable data protection laws.
The Data Controller responsible for processing personal data is:
Chilowattora Srl
Registered Office: Via Rivierasca dell'Adda 273 - 24033 Calusco d'Adda (BG), Italy
VAT Number: 04684420161
Email: hello@buyyournumber.app
Certified Email (PEC): chilowattorasrl@pec.it
When you use BYN, we may collect the following categories of personal data.
To protect the platform and users from abuse, we may process security-related information such as:
These checks are used exclusively for security purposes.
When you purchase digital content through Apple App Store or Google Play Store, transaction information may be processed.
BYN does not collect or store payment card details. Payments are processed exclusively by:
For the purposes of this Privacy Policy, a "Digital Identity" means a unique numerical identifier registered and managed within the BYN ecosystem and associated with a user's account.
We process information related to your BYN account activities, including:
If you grant permission, BYN may send push notifications to your device. Notification data (such as delivery tokens) is processed solely for the purpose of delivering notifications.
Notifications may include:
You may withdraw this permission at any time through your device's operating system settings.
Certain information associated with your BYN profile may be visible to other users of the platform, including:
The following information remains private and is never visible to other users:
Our Website uses cookies and similar technologies for the following purposes:
Google Analytics may set cookies on your device and may transfer data to Google servers in the United States. Google processes this data in accordance with its own Privacy Policy. We use Google Analytics with IP anonymization enabled where supported.
Analytics cookies are only placed with your prior consent, which you can provide or withdraw through the cookie consent banner displayed on your first visit, or at any time through your browser settings. You may also opt out of Google Analytics tracking at any time by installing the Google Analytics Opt-out Browser Add-on.
We do not use cookies for advertising, retargeting, or profiling purposes.
We process personal data only when a valid legal basis exists.
We process personal data to:
We process personal data where necessary to:
We process certain information to:
Where required by law, we process data based on your consent, including:
You may withdraw consent at any time.
BYN may use automated algorithms to classify numerical identities and assign rarity scores. These classifications are used exclusively for platform functionality and do not produce legal effects or automated decisions concerning users under Article 22 GDPR.
We retain personal data only for as long as necessary to provide the Services and comply with legal obligations.
Account information is retained while your account remains active.
Users may request deletion of their account at any time. Upon deletion:
Such operational rules may evolve over time and are described in the Terms of Service.
Financial and accounting records may be retained for up to 10 years where required by applicable law.
We do not sell personal data. Personal data may be shared only with trusted service providers acting on our behalf. These providers may include:
All providers process data under appropriate contractual safeguards.
Some service providers may process data outside the European Economic Area (EEA). Where such transfers occur, appropriate safeguards are implemented, including Standard Contractual Clauses (SCCs), Adequacy Decisions, or other lawful transfer mechanisms recognized by GDPR.
We implement appropriate technical and organizational measures to protect personal data. These measures include encryption in transit, secure authentication systems, access controls, monitoring and abuse prevention systems, and secure credential storage.
User credentials and authentication tokens may be stored using secure operating-system technologies such as Apple Keychain and Android Keystore. Users are responsible for maintaining the security of their devices.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR.
Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by Article 34 GDPR, through the App, Website, or by email where feasible.
BYN is not intended for children under the minimum age required by applicable law. Users must be at least 16 years old, or the minimum age permitted under local regulations, to use the Services. If we become aware that personal data has been collected from a child in violation of applicable law, we will take reasonable steps to remove such information.
The App integrates third-party software development kits (SDKs) that may independently collect certain data as described in their own privacy policies. These include:
We encourage you to review the privacy policies of these providers to understand how they process your data independently.
BYN may generate anonymous and aggregated statistics relating to platform usage, numerical identities, collections, searches, interactions, and community activity.
Such information does not identify individual users and may be used for:
Aggregated statistics may be displayed publicly within the App, Website, or marketing materials without identifying individual users.
Users may voluntarily publish content and information within the BYN platform, including:
Content intentionally made public by users may be visible to other users and may be surfaced through platform features designed to improve discoverability and engagement.
Users remain responsible for the information they choose to publish publicly through the Services.
Users should avoid publishing personal or sensitive information through public profile elements.
Under GDPR, you may exercise the following rights:
Requests may be submitted to: hello@buyyournumber.app. We will respond within one month as required by GDPR, with the possibility of extending this period by a further two months for complex or numerous requests.
For security reasons, identity verification may be required before fulfilling certain requests.
If you believe that your personal data is being processed unlawfully, you may lodge a complaint with your local data protection authority. For Italy:
Garante per la Protezione dei Dati Personali
https://www.garanteprivacy.it
We may update this Privacy Policy from time to time. Any material changes will be communicated through the App, Website, or by email where appropriate. We will provide reasonable notice of material changes where required by applicable law. The updated date at the top of this page will always reflect when the policy was last revised. Continued use of the Services following the effective date of any update constitutes acknowledgment of the revised Privacy Policy.